Speaking purely hypothetically here as someone who has no information:
It is a frontier cutting edge model with a lot of test time compute and agentic swarm. The chance that it was able to access some data no one thought it should access that would help it solve the problem is at least nonzero.
We’ve seen those in the past few weeks.
fwiw I think it is _extremely_ unlikely that user data had any influence here - there is no way OAI would pull user transcripts for this, or knowingly train on it in a way that would've influenced this.
I think its pretty important people don't run away with 'your user data isn't safe in codex' - because it surely is (based on everything I can assume from the outside)